summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)AuthorFilesLines
2008-01-30security: compile capabilities by defaultsergeh@us.ibm.com1-0/+1
2008-01-30selinux: make selinux_set_mnt_opts() staticAdrian Bunk1-2/+2
2008-01-30SELinux: Add warning messages on network denial due to errorPaul Moore3-8/+40
2008-01-30SELinux: Add network ingress and egress control permission checksPaul Moore1-122/+280
2008-01-30SELinux: Allow NetLabel to directly cache SIDsPaul Moore5-134/+55
2008-01-30SELinux: Enable dynamic enable/disable of the network access checksPaul Moore4-13/+83
2008-01-30SELinux: Better integration between peer labeling subsystemsPaul Moore6-100/+208
2008-01-30SELinux: Add a new peer class and permissions to the Flask definitionsPaul Moore4-0/+26
2008-01-30SELinux: Add a capabilities bitmap to SELinux policy version 22Paul Moore6-8/+185
2008-01-30SELinux: Add a network node caching mechanism similar to the sel_netif_*() fu...Paul Moore5-17/+416
2008-01-30SELinux: Only store the network interface's ifindexPaul Moore3-6/+15
2008-01-30SELinux: Convert the netif code to use ifindex valuesPaul Moore6-125/+155
2008-01-30NetLabel: Add IP address family information to the netlbl_skbuff_getattr() fu...Paul Moore3-15/+38
2008-01-30NetLabel: Add secid token support to the NetLabel secattr structPaul Moore2-6/+9
2008-01-29[NETFILTER]: Introduce NF_INET_ hook valuesPatrick McHardy1-2/+2
2008-01-26selinux: fix labeling of /proc/net inodesStephen Smalley1-0/+3
2008-01-25Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmo...Linus Torvalds8-277/+564
2008-01-25Kobject: convert remaining kobject_unregister() to kobject_put()Greg Kroah-Hartman1-1/+1
2008-01-25kobject: convert kernel_kset to be a kobjectGreg Kroah-Hartman1-1/+1
2008-01-25kset: convert kernel_subsys to use kset_createGreg Kroah-Hartman1-1/+1
2008-01-25kobject: convert securityfs to use kobject_createGreg Kroah-Hartman1-6/+5
2008-01-25kobject: remove struct kobj_type from struct ksetGreg Kroah-Hartman1-2/+2
2008-01-25selinux: make mls_compute_sid always polyinstantiateEamon Walsh1-9/+2
2008-01-25security/selinux: constify function pointer tables and fieldsJan Engelhardt2-3/+3
2008-01-25security: add a secctx_to_secid() hookDavid Howells3-0/+18
2008-01-25security: remove security_sb_post_mountroot hookH. Peter Anvin2-11/+0
2008-01-25Security: add get, set, and cloning of superblock security informationEric Paris4-254/+541
2008-01-25security/selinux: Add missing "space"Joe Perches1-1/+1
2008-01-22Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmo...Linus Torvalds2-4/+5
2008-01-22Fix filesystem capability supportAndrew G. Morgan1-3/+10
2008-01-22selinux: fix memory leak in netlabel codePaul Moore2-4/+5
2007-12-05Security: allow capable check to permit mmap or low vm spaceEric Paris1-1/+1
2007-12-05SELinux: detect dead booleansStephen Smalley1-13/+30
2007-12-05SELinux: do not clear f_op when removing entriesStephen Smalley1-27/+1
2007-11-29file capabilities: don't prevent signaling setuid root programsSerge E. Hallyn1-0/+9
2007-11-15file capabilities: allow sigcont within sessionSerge E. Hallyn1-0/+4
2007-11-08SELinux: add more validity checks on policy loadStephen Smalley7-38/+118
2007-11-08SELinux: fix bug in new ebitmap code.KaiGai Kohei1-1/+1
2007-11-08SELinux: suppress a warning for 64k pages.Stephen Rothwell1-6/+7
2007-10-23Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmo...Linus Torvalds1-5/+1
2007-10-23SELinux: always check SIGCHLD in selinux_task_waitEric Paris1-5/+1
2007-10-22capabilities: clean up file capability readingSerge E. Hallyn1-8/+15
2007-10-19pid namespaces: define is_global_init() and is_container_init()Serge E. Hallyn1-1/+2
2007-10-19sparse pointer use of zero as nullStephen Hemminger1-1/+1
2007-10-19V3 file capabilities: alter behavior of cap_setpcapAndrew Morgan2-14/+61
2007-10-17security/ cleanupsAdrian Bunk5-118/+1
2007-10-17Implement file posix capabilitiesSerge E. Hallyn6-43/+313
2007-10-17security: Convert LSM into a static interfaceJames Morris8-71/+961
2007-10-17KEYS: Make request_key() and co fundamentally asynchronousDavid Howells5-317/+335
2007-10-17SELinux: kills warnings in Improve SELinux performance when AVC missesKaiGai Kohei2-6/+7